Triskele Labs Blog

Citrix NetScaler ADC & Citrix NetScaler Gateway Remote Code Execution Vulnerabilities (CVE-2026-88771, CVE-2026-88772)

Written by  Brandon Sawyer | Sep 28, 2026, 6:16:19 AM

Published: Mon 28 September 2026

Prepared by: Brandon Sawyer, Vulnerability Analyst

Purpose

On 27 September 2026, Citrix published security bulletin CTX697096, disclosing eight vulnerabilities (CVE-2026-88771 to CVE-2026-88778) in Citrix NetScaler ADC and NetScaler Gateway. This bulletin focuses on two of them, CVE-2026-88771 and CVE-2026-88772: critical remote code execution (RCE) vulnerabilities that Citrix, the US Cybersecurity and Infrastructure Security Agency (CISA) and the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) all confirm were exploited as zero-days before a fix was available. CISA added both to its Known Exploited Vulnerabilities (KEV) catalogue on the same day.

ASD's ACSC has not yet received reports of confirmed exploitation in Australia. However, organisations running NetScaler ADC or NetScaler Gateway should treat patching as an emergency priority and assess appliances for compromise, given the pre-disclosure exploitation.

Vulnerability Details

CVE-2026-88771 is an improper input validation vulnerability (CWE-20) with a CVSSv4.0 base score of 9.5 (Critical). It allows an unauthenticated attacker to execute arbitrary commands. It affects every NetScaler ADC and NetScaler Gateway deployment on a vulnerable version, including the default configuration, with no additional feature required. Because no special configuration is needed, every internet-reachable appliance on an affected build should be considered exposed.

CVE-2026-88772 is a memory overflow vulnerability (CWE-119) with a CVSSv4.0 base score of 9.5 (Critical). It can lead to remote code execution or denial of service when DTLS is configured, and DTLS is enabled by default on VPN virtual servers. As a result, a NetScaler Gateway is affected unless DTLS has been explicitly disabled.

A threat actor needs only network access, not a valid account, to exploit either flaw. Internet-facing Gateway, VPN and AAA virtual servers should be prioritised.

The Citrix bulletin addresses six further NetScaler vulnerabilities, CVE-2026-88773 to CVE-2026-88778. These depend on specific configurations and include HTTP request smuggling, memory overflow and denial of service issues. None had been reported as exploited at the time of writing. Citrix has provided instructions for customers to check whether their device meets the preconditions for each of these configuration-dependent CVEs. Of these, CVE-2026-88778 is fixed by enabling Enhanced ISN Generation rather than by the upgrade alone.

These vulnerabilities are separate from CVE-2026-19490. That authentication bypass was fixed on 19 August 2026 and added to the KEV catalogue on 9 September. Appliances patched for CVE-2026-19490 remain vulnerable unless they run one of the fixed builds listed below.

Discovery and Disclosure Timeline 

Date Event
26 Sept 2026  NetScaler administrators report being told by suppliers and security teams to shut appliances down, following a private pre-notification from the Dutch National Cyber Security Centre (NCSC-NL). watchTowr publicly warns that multiple unpatched NetScaler RCE vulnerabilities are being exploited after being identified during forensic investigations. 
27 Sept 2026 Citrix publishes security bulletin CTX697096, confirms both vulnerabilities and releases fixed builds. CISA adds CVE-2026-88771 and CVE-2026-88772 to the KEV catalogue. 
Ongoing This remains an emerging situation. Organisations should monitor Citrix's security bulletin and NetScaler Console for updated guidance and indicators of compromise as they are published. 

 

Impact

NetScaler ADC and NetScaler Gateway sit at the network edge, handling VPN and remote access, load balancing and user authentication for staff and customers connecting to internal applications. Successful exploitation gives a threat actor unauthenticated code execution on the appliance. That can expose:

  • Control of the appliance, including the ability to install persistence mechanisms or additional tooling
  • Session data, credentials, secrets, certificates and private keys stored on or passing through the appliance
  • A foothold at the perimeter for lateral movement into internal systems and applications
  • Service disruption, as CVE-2026-88772 can also result in denial of service

Because both vulnerabilities were exploited before a fix existed, patching does not show whether a threat actor gained access first. After a NetScaler zero-day was exploited against Dutch organisations in 2025, NCSC-NL warned that updating alone did not remove the risk, because an attacker could keep access gained before the patch.

Mitigation

Primary Remediation

The primary remediation is to upgrade all NetScaler ADC and NetScaler Gateway appliances to the fixed build for their release line:

Product Affected Versions Fixed Release
NetScaler ADC and NetScaler Gateway 14.1  Before 14.1-73.37  14.1-73.37
NetScaler ADC and NetScaler Gateway 13.1  Before 13.1-64.23  13.1-64.23 
NetScaler ADC 14.1-FIPS  Before 14.1-73.37 FIPS  14.1-73.37 FIPS 
NetScaler ADC 13.1-FIPS and 13.1-NDcPP  Before 13.1-37.279  13.1-37.279 

Secure Private Access hybrid deployments that use NetScaler instances are also affected. The bulletin covers customer-managed appliances, and Citrix updates its own managed cloud services. The 13.1 fix was released even though that branch reached End of Maintenance on 15 September 2026. Organisations on 13.1 should plan migration to 14.1.

Before upgrading a 13.1 appliance, run show ns variable. If it returns any variables, install 13.1-64.24 instead to avoid a known reboot loop during the upgrade. Also enable Enhanced ISN Generation to address CVE-2026-88778.

Citrix has not published a workaround for either exploited vulnerability, so upgrading is the only way to close the entry point. CISA urges organisations to check for compromise before patching where possible, and to preserve forensic evidence first, because updates may cause a loss of forensic visibility. Evidence collection should therefore come before the upgrade on any internet-facing appliance.

In addition to applying the update, ASD's ACSC recommends that organisations review the preconditions for each of the eight CVEs to understand where their devices may have been vulnerable to exploitation. It also advises organisations to use their internal security assessments and business plans to decide how to prioritise implementing the update. Given confirmed pre-patch exploitation of CVE-2026-88771, which affects all configurations, internet-facing appliances should be at the top of that list.

Compensating Controls

No workaround addresses these vulnerabilities directly. Where an immediate upgrade cannot be completed, the following measures can reduce exposure in the interim:

  • Isolate the appliance from the network, or take it offline, until it can be upgraded. Several organisations did this before patches were released.
  • Keep the NetScaler management interface off the public internet. Citrix's compromise guidance says the NetScaler Management Services should never be publicly exposed.
  • Where DTLS is not operationally required, disabling it on VPN virtual servers removes the stated precondition for CVE-2026-88772. This does not affect CVE-2026-88771, which applies to default configurations.

These measures reduce the attack surface but do not fix the underlying flaws. They also will not remove any persistence a threat actor established before they were applied.

Hardening and Longer-Term Actions

Organisations that identify or cannot rule out compromise should follow Citrix's guidance for suspected compromise. That guidance covers the following steps:

  • Change every service account password and secret stored on the appliance.
  • Reset the passwords of users who authenticated through it.
  • Revoke its certificates and private keys.

NetScaler logs should also be forwarded to a centralised SIEM so they remain available for retrospective investigation.

Detection

Indicators and Log-Based Detection

Citrix has made indicators of compromise (IOCs) available through NetScaler Console. Organisations can run the IOC scan on the Console Security Advisory page, which requires version 14.1-73.36 or later with telemetry enabled, or request the IOCs from Citrix Support. These indicators should be treated as a starting point. Citrix warns that the IOCs do not cover every technique, so a clean result does not prove the appliance is uncompromised.

Recommended Detection and Hunting Activities

  • Preserve evidence from each exposed appliance before upgrading. This should include logs, a snapshot, a support bundle and a core dump.
  • Run the NetScaler Console IOC scan, or obtain IOCs from Citrix Support, across every NetScaler instance, including HA pairs and cluster members.
  • Review logs held off-appliance (remote syslog, NetScaler Console, SIEM, firewall and proxy logs) for unexpected outbound connections, unusual administrative activity or unfamiliar sessions. Focus on the period leading up to the 27 September 2026 disclosure.
  • Wherever a CVE's preconditions were met, review device logs for suspicious activity consistent with the attacks that CVE enables, as ASD's ACSC recommends.
  • If any indicator is identified, or an internet-facing appliance was running an affected build, treat the environment as potentially compromised. Rotate credentials and cryptographic material and engage incident response.
  • Organisations that are impacted or suspect compromise can contact ASD's ACSC on 1300 CYBER1 (1300 292 371) and should engage Citrix Support.

MDR customers: Triskele Labs will continue tuning detections and analysing IOCs, as they become publicly available for behaviours consistent with the exploitation of CVE-2026-88771 and CVE-2026-88772 across supported log sources. 

Vulnerability Management customers: Environments will be assessed for vulnerable versions of Citrix NetScaler ADC and NetScaler Gateway affected by CVE-2026-88771 and CVE-2026-88772 once detections are made available. Any findings will be communicated through priority channels. 

This remains an emerging situation. We urge all organisations running Citrix NetScaler ADC or NetScaler Gateway to stay up to date with information from trusted vendor and government sources as further guidance is published. 

References